Skip to main content
evoICT Solutions — Evolution in IT
  • Home
  • Solutions
  • Services
  • Cyber Resilience
    • Guides
    • News
    • FAQ
  • About Us
    • English
    • Ελληνικά
    • Български
    • Deutsch
    • Italiano
    • Español
  • Get Protected
  1. Home
  2. Regulatory compliance

Legal & compliance

  • Privacy policy
  • Cookie policy
  • Terms of use
  • Accessibility statement
  • Regulatory compliance

Legal & compliance

Regulatory compliance

Last updated: 2026-08-18

How evoICT Solutions positions itself against NIS2, GDPR, the EU AI Act, the Cyber Resilience Act, DORA and the other frameworks that apply to managed service and managed security service providers.

Why this page exists

Managed service providers sit inside their clients' regulatory perimeter. When a client is in scope of a regulation, obligations flow to us as a supplier through contracts and supply chain requirements, and in some cases apply to us directly. This page sets out our position honestly: what applies to us, what we have in place, and where work is ongoing.

GDPR and Greek data protection law

We process personal data as a controller for our own business and as a processor for client environments, under agreements meeting Article 28. We maintain records of processing, a sub-processor list, defined retention periods, a breach notification procedure aligned to the 72-hour rule, and confidentiality commitments from staff. Greek Law 4624/2019 supplements the GDPR nationally and applies to our processing in Greece.

NIS2 (Directive EU 2022/2555)

NIS2 raises cybersecurity requirements across essential and important entities, makes management accountable, and explicitly extends risk management into the supply chain, including managed service providers and managed security service providers. Where our clients are in scope, our services are part of their compliance evidence.

We support clients with scoping, risk assessment, technical measures, incident reporting readiness and staff training. We also apply the same baseline internally: multi-factor authentication, patch management, access control, tested backups, logging and an incident response procedure. National transposition timing and supervisory practice vary by member state, and we track the position in Greece.

EU AI Act (Regulation EU 2024/1689)

The AI Act applies obligations according to role and risk level. For most of our services we are a deployer of AI systems rather than a provider. For TagPulse.ai, which uses AI-driven anomaly detection, we act as a provider and treat the following as our responsibilities: clear documentation of intended purpose and limitations, transparency to users that AI is in use, human oversight of consequential outputs, data governance for training and evaluation, and logging.

Anomaly detection in an IT security context is not, in itself, a prohibited practice, and we do not use the system for emotion inference, biometric categorisation or social scoring. Obligations under the Act phase in on different dates, and we align our documentation with the applicable deadline for each requirement.

EU Cyber Resilience Act (Regulation EU 2024/2847)

The CRA sets cybersecurity requirements for products with digital elements placed on the EU market, covering secure development, vulnerability handling, a coordinated disclosure policy, security updates over a defined support period, and reporting of actively exploited vulnerabilities. Its obligations apply on a staggered timeline, with the reporting duties arriving before the main body of requirements.

For software we publish ourselves, we treat the CRA as the design target: a documented secure development process, a software bill of materials, a published contact route for vulnerability reports, and a defined support period communicated to users. For third-party products we resell or manage, the manufacturer carries the CRA obligations, and we monitor their advisories and apply updates for our clients.

Other frameworks that reach our work

  • ISO/IEC 27001: we work to an information security management approach modelled on the standard, and support clients pursuing certification. We describe this as readiness support rather than certification.
  • DORA (Regulation EU 2022/2554): where we serve financial entities, we may be treated as an ICT third-party service provider, which brings contractual, register and exit strategy requirements.
  • ePrivacy Directive and Greek implementation: relevant to electronic communications and to storage on user devices, addressed in our cookie policy.
  • NIS2 supply chain clauses, ISO 22301 business continuity practice, and client-specific sector rules in health, energy and transport, which we meet through contractual commitments and evidence.
  • Whistleblowing, accounting and consumer protection rules that apply to us as a Greek company.

Vulnerability reporting

If you believe you have found a security vulnerability in this website or in one of our tools, please report it to us using the contact details below. We ask that you give us a reasonable period to remediate before public disclosure, and we commit to acknowledging your report and keeping you informed.

Status and honesty note

Compliance is a continuing process, not a certificate on a wall. Where this page says we support a framework, it means we help clients meet it and apply the same practices ourselves. It does not claim independent certification unless a certificate is named. If you need evidence for an audit or a supplier questionnaire, ask us and we will provide what we hold.

Contact

  • AddressevoICT Solutions, Plateia Alonion 1, Alonia, Pieria 60300, Greece
  • Phone+30 6988 30 000 6
  • Email[email protected]
evoICT Solutions

Evolution in IT — cyber resilience and ICT services for organisations that cannot afford to stop.

Navigation

  • Home
  • Solutions
  • Services
  • Cyber Resilience

Resources

  • Guides
  • News
  • FAQ
  • About Us

Solutions

  • SecureDomainScore (opens in a new tab)
  • WhatIsMyTenantID (opens in a new tab)
  • TagPulse.ai (opens in a new tab)

Legal & compliance

  • Privacy policy
  • Cookie policy
  • Terms of use
  • Accessibility statement
  • Regulatory compliance
© 2026 evoICT Solutions — All rights reserved NIS2 · GDPR · ISO 27001 readiness support Back to top ↑

Accessibility

Text size
Light theme
Maximum contrast
Reduce motion
Underline links
Readable font
Wider spacing

Your settings are saved on this device.